Release date:
Updated on:
Affected Systems:
D-Link DAP-1350 <= 1.14
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67310
D-Link DAP-1350 is a mini-type wireless router.
The input in the D-Link DAP-1350 1.14 (HW version A1) login form is used in SQL queries if it is not properly filtered, this allows attackers to inject arbitrary SQL code, bypass authentication, and perform unauthorized database operations.
<* Source: SensePost Information Security
Link: http://secunia.com/advisories/58254/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://securityadvisories.dlink.com/security/publication.aspx? Name = SAP10023
This article permanently updates the link address: